EDBT 2026 Demo / reviewers in the wild / expert
Ben Niu 0001
dblp:90/4149-1
· DBLP profile ↗
72ranked-venue papers
21as first author
32since 2021 · last 2026
0000-0003-2898-7495ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 42 · 17 first-author · 14 since 2021Security and privacy · 13 · 2 first-author · 8 since 2021Databases, data management, data science and information retrieval · 5 · 2 since 2021Systems, architecture and hardware · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LFS: A Locally Private Framework for Degree Statistic Estimation With Laplace MechanismabstractAs a fundamental task in graph data analysis, degree statistic estimation serves as the foundation for many complex tasks. Local differential privacy (LDP) preserves the privacy inherent in raw degrees without a trusted third party. Existing methods struggle to balance different types of degree statistics. They either introduce excessive noise when estimating degree distribution due to not fully leveraging the properties of edge LDP, or are limited to polynomial statistic estimation only. We design a locally private framework for degree statistic estimation (LFS), using Laplace mechanism to provide appropriate privacy protection under edge LDP. LFS can estimate three types of degree statistics: polynomial, distribution and single-point. According to degrees with Laplace noise, we transform degree distribution estimation into a linear regression problem, then post-process the estimated distribution to mitigate the excessive smoothing introduced by the regularization term. We also achieve single-point statistic estimation considering the degree distribution and properties of Laplace noise. Systematic experiments on five datasets demonstrate that LFS consistently outperforms existing methods in four utility metrics. Yuke Hu, Shiqi Zhou, Fenghua Li 0001, Ben Niu 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Training Data Attribution: Was Your Model Secretly Trained On Data Created By Mine?abstractThe emergence of text-to-image models has recently sparked significant interest, but the attendant is a looming shadow of potential infringement by violating user terms. Specifically, an adversary may exploit data created by a commercial model to train their own without proper authorization. To address such risk, it is crucial to investigate the attribution of a suspicious model's training data by determining whether its training data originates, wholly or partially, from a specific source model. To trace the generated data, existing methods need to apply additional watermarks during either the training or inference phases of the source model. However, these methods are impractical for pre-trained models that have been released, especially when model owners lack security expertise. To tackle this challenge, we propose an injection-free training data attribution method for text-to-image models. It can identify whether a model's training data stems from a certain source model without adding additional watermarks on the source model. The rationale of our method lies in the inherent memorization characteristic of text-to-image models. The memorization of training data is inherited through the data generated by the source model to the model trained on that data, making the source model and the infringing model exhibit consistent behaviors on specific samples. Therefore, from instance-level, we develop detection-based and generation-based strategies to uncover these distinct samples and using them as inherent watermarks to verify if a suspicious model originates from the source model. Besides, we also propose a statistical-level attribution method, utilizing the shadow model technique to train an attribution discriminator. Experiments demonstrate that the attribution accuracy and AUC scores of our methods are over 80% even when the infringing model only uses a small proportion of generated data. Hao Wu 0067, Lingcui Zhang, Fengyuan Xu, Jin Cao 0001, Fenghua Li 0001, Ben Niu 0001 |
KDD (2) | 7 |
| 2025 | FlexiGrain: A Flexible and Fine-Grained Privacy Control Framework for Dynamic Social NetworksabstractBalancing information sharing with privacy preserving is a fundamental challenge for users in social networks, where the generation of effective privacy control strategies is a critical control mechanism. Existing efforts are typically coarse-grained (e.g., globally uniform) and static to adapt to dynamic scenarios, thus failing to achieve a precise privacy-utility trade-off. In this paper, we propose a FlexiGrain framework, jointly utilizing information diffusion prediction and multi-objective optimization to generate fine-grained privacy control strategies. In this framework, we design a DHGCNUI model, which integrates intimacy and propagation behavior features to produce a highly accurate user activation probability matrix; then we propose a privacy control strategy generation algorithm, named PDO-NSGA-II, which performs multi-objective optimization to simultaneously maximize information utility and minimize privacy risk. Extensive experiments are conducted on two public datasets, and the results demonstrate the FlexiGrain framework outperforms the state-of-the-art methods in terms of effectiveness and flexibility. Ben Niu 0001, Fanyu Gan, Jinyu Peng, Jin Cao 0001 |
TrustCom | 1 |
| 2025 | NSAA: A Network Slice Access Authentication and Service Authorization Scheme for Integrated Satellite-Terrestrial NetworkabstractIntroducing slicing into integrated satellite-terrestrial networks enables the flexible deployment of network resources and being adaptable for more new applications. However, the heterogeneity of integrated satellite-terrestrial network poses challenges to network resource access control. To ensure users can securely and efficiently access service across multiple management domains, we propose a network slice access authentication and service authorization scheme based on a sharding permissioned blockchain. Slice tenants and wireless network operators with management control act as consortium blockchain nodes, which are divided into shards, and the blockchain is maintained in parallel by multiple shards. First, an efficient public ledger is constructed to establish decentralized trust and manage user identity and service authorization information. Second, utilizing the trapdoor collision resistance of the chameleon hash, users can fully self-select their secret key and generate authentication credentials to register on the blockchain without key escrow problem. When users move into a new network domain, the mutual authentication between users and the visited network can be quickly completed. The session key is negotiated based on the Diffie-Hellman ephemeral protocol with perfect forward secrecy. Then, the editable transaction blocks, storing network slice authorization information and slice templates, are linked using chameleon hashes. This allows the access permissions of slice resources to be dynamically adjusted and easily queried by the service-providing wireless network operators. Performance evaluation and security simulations demonstrate the correctness of the scheme, showing that it can achieve secure access to integrated satellite-terrestrial network slice services with low computational and communication overhead. Yurong Luo, Jin Cao 0001, Ruhui Ma, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Internet Things J. | 5 |
| 2025 | Everyone's Privacy Matters! An Analysis of Privacy Leakage from Real-World Facial Images on Twitter and Associated User BehaviorsabstractOnline users often post facial images of themselves and other people on online social networks (OSNs) and other Web 2.0 platforms, which can lead to potential privacy leakage of people whose faces are included in such images. There is limited research on understanding face privacy in social media while considering user behavior. It is crucial to consider privacy of subjects and bystanders separately. This calls for the development of privacy-aware face detection classifiers that can distinguish between subjects and bystanders automatically. This paper introduces such a classifier trained on face-based features, which outperforms the two state-of-the-art methods with a significant margin (by 13.1% and 3.1% for OSN images, and by 17.9% and 5.9% for non-OSN images). We developed a semi-automated framework for conducting a large-scale analysis of the face privacy problem by using our novel bystander-subject classifier. We collected 27,800 images, each including at least one face, shared by 6,423 Twitter users. We then applied our framework to analyze this dataset thoroughly. Our analysis reveals eight key findings of different aspects of Twitter users' real-world behaviors on face privacy, and we provide quantitative and qualitative results to better explain these findings. We share the practical implications of our study to empower online platforms and users in addressing the face privacy problem efficiently. Yuqi Niu, Weidong Qiu, Peng Tang 0002, Lifan Wang, Shujun Li 0001, Nadin Kökciyan, Ben Niu 0001 |
Proc. ACM Hum. Comput. Interact. | 8 |
| 2025 | U-DPAP: Utility-aware Efficient Range Counting on Privacy-preserving Spatial Data FederationabstractRange counting is a fundamental operation in spatial data applications. There is a growing demand to facilitate this operation over a data federation, where spatial data are separately held by multiple data providers (a.k.a., data silos). Most existing data federation schemes employ Secure Multiparty Computation (SMC) to protect privacy, but this approach is computationally expensive and leads to high latency. Consequently, private data federations are often impractical for typical database workloads.This challenge highlights the need for a private data federation scheme capable of providing fast and accurate query responses while maintaining strong privacy. To address this issue, we propose U-DPAP, a utility-aware efficient privacy-preserving method. It is the first scheme to exclusively use differential privacy for privacy protection in spatial data federation, without employing SMC. Moreover, it combines approximate query processing to further enhance efficiency. Our experimental results indicate that a straightforward combination of the two techniques results in unacceptable impacts on data utility. Thus, we design two novel algorithms: one to make differential privacy practical by optimizing the privacy-utility trade-off, and another to address the efficiency-utility trade-off in approximate query processing. The grouping-based perturbation algorithm reduces noise by grouping similar data and applying noise to the groups. The representative data silos selection algorithm minimizes approximate error by selecting representative silos using the similarity between data silos. We rigorously prove the privacy guarantees of U-DPAP. Moreover, experimental results demonstrate that U-DPAP enhances data utility by an order of magnitude while maintaining high communication efficiency. Yahong Chen, Xiaoyi Pang, Ben Niu 0001, Shengnan Hu |
Proc. ACM Manag. Data | 5 |
| 2025 | Recipient-Aware Photo Automatic Deletion Control Policy Recommendation Scheme in Online Social NetworksabstractContent sharing, whether in Online Social Networks (OSNs) or even in the Internet of Things (IoT), serves as a pivotal link in the flow of data. To better protect the privacy of shared content, current OSNs allow sharers to manually set policies for uploaded content. However, this method of policy setting is not suitable for scenarios where IoT is deeply integrated with OSNs, as IoT devices often share content frequently and automatically. To address this issue, we propose the design, implementation, and evaluation of SmartCircles, a personalized photo-sharing and automatic deletion scheme. SmartCircles can function as a plugin within existing OSNs, supporting operations on various smart devices. It encompasses the following steps: a) Before sharing a photo, calculate the intimacy level depicted in the photo and the sharer's willingness to share. b) Before the recipient views the photo, calculate the intimacy between the sharer and the recipient, and evaluate feedback from the recipient. c) Based on the results computed above and a trade-off between profit and loss, recommend a recipient-aware automatic deletion control policy for the photo. We implement a prototype of SmartCircles, and the evaluation results demonstrate its effectiveness with an accuracy rate of policy recommendations reaching approximately 92%. Haiyang Luo, Zhe Sun 0005, Yunqing Sun, Ang Li 0005, Binghui Wang, Jin Cao 0001, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | A Formal Analysis of 5G ProSe AKA Protocols for U2N Relay Communicationabstract5G Proximity-based Service (ProSe) UE-to-Network (U2N) Relay can help a remote 5G User Equipment (UE) out of coverage connect with the network. The 3GPP committee has provided the standard Authentication and Key Agreement (AKA) protocols to achieve secure access for a Remote UE and establish a secure link between a Remote UE and a U2N Relay. However, the security of these AKA protocols is a remaining issue. At first, we present two detailed 5G ProSe AKA protocols over Control Plane (CP) and User Plane (UP) for U2N Relay communication referring to multiple related standards, then transform the security requirements for 5G ProSe U2N Relay communication as formal security properties, and provide two formal faithful security models for the 5G ProSe AKA protocols. We adopt the state-of-the-art formal verification tool Tamarin to achieve automated security analysis on two models through new proof strategies, and then find some significant and unexpected flaws. Finally, we propose corresponding measures that have least impact on standards based on the analysis on the attacks. Given that the version of Release 17 (R17) of the 3GPP standard has just been frozen, our work can provide a reference for the subsequent evolution of the protocols in 5G ProSe. Xiongpeng Ren, Jin Cao 0001, Ben Niu 0001, Yinghui Zhang 0002, Lihui Xiong, Yurong Luo, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | AotmAuth: Atomic Function Module-Based 6G Authentication Protocol Combination FrameworkabstractOver the years, various mobile communication technologies have been developed and operated simultaneously, which made the mobile communication networks evolved from single-mode access to complex heterogeneous integration. The current 5 G has already accommodated diverse terminals through multiple access paths, but the upcoming 6 G ambitiously aims to achieve ubiquitous connectivity through space-air-ground-sea integrated networks. However, traditional authentication and management protocols, such as EPS-AKA and 5G-AKA, are designed for specific networks and lack the flexibility to adapt to the diverse and dynamic requirements of 6G. This limitation will inevitably result in complex management, enormous overhead, and unmanageable security risks. In this paper, we present an atomic functional module-based 6G authentication protocol combination framework (AotmAuth) to decompose the existing authentication protocols into reusable basic modules, and by combining these modules, flexible authentication protocols can be constructed to meet specific security and performance requirements. The proposed approach can significantly improve the robustness, extensibility and dependability of protocols cobmination, by simplify protocol design, enhance adaptability across diverse scenarios and facilitate quick improvements by replacing or adjusting specific modules. To validate the effectiveness of the proposed solution, we design and develop a 6G heterogeneous access security testbed. The experimental results show that the proposed framework can achieve higher authentication efficiency while ensuring security compared to traditional authentication methods. Wei Yi 0001, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Efficient Vehicle Secure Scheduling and Access Authentication Scheme for 5G-Integrated Emergency Rescue ScenarioabstractWith urban population density on the rise, emergency incidents are increasing in both frequency and complexity, placing growing pressure on existing rescue systems. Meanwhile, issues such as slow response times, inadequate coordination mechanisms, and inefficient information exchange further exacerbate the challenges faced by these systems. The integration of Vehicle-to-Everything (V2X) communication and 5G technology offers unprecedented capabilities, such as ultra-low latency and high data throughput, which are critical for real-time coordination and decision-making in emergency rescue scenarios. To establish secure and efficient vehicle communication in 5G and V2X-enabled emergency rescue scenarios, we propose an efficient vehicle secure scheduling and access authentication scheme based on certificateless cryptography and multireceiver signcryption. In this scheme, the command and control center can securely dispatch rescue fleets based on disaster conditions. By enabling mutual authentication and key agreement between rescue vehicles and roadside units, the scheme ensures the reliable and swift exchange of rescue information and instructions. In addition, to address unexpected situations such as traffic congestion, we design a route-switching mechanism. Furthermore, in order to mitigate potential malicious behavior, a vehicle legitimacy revocation mechanism is implemented to ensure the normal operation of the system. The security of the scheme is verified through formal analysis and informal analysis. Performance analysis demonstrates that the scheme offers significant advantages over existing ones in terms of signaling overhead, communication overhead, computational overhead, and energy efficiency. Jin Cao 0001, Yiqing Xiong, Ruhui Ma, Yinghui Zhang 0002, Ben Niu 0001, Peijie Yin, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 7 |
| 2025 | A Hierarchical Encrypted Compression Scheme for Intra-Vehicle NetworkabstractThe CAN bus is the most widely used bus for intra-vehicle communication due to its high transmission stability, excellent real-time communication capability, and relatively low cost. As the number of ECUs grows, the CAN bus load increases and thus raises the possibility of data transmission delays and errors. Message compression based on the differential algorithm has been proposed to reduce the CAN bus load. However, current works do not consider the security problems of the CAN bus. Attackers can manage to acquire the original messages before compression and disturb the message statistics to decrease compression rate by injecting malicious frames. In this paper, we propose a secure compression mechanism for the intra-vehicle network, including an improved compression algorithm, a stream key distribution scheme, and a hierarchical encryption scheme. Formal verification results show that the proposed scheme can achieve mutual authentication, message confidentiality and integrity, resist replay attacks, and support secure compression. Evaluations using real vehicle data on 16 MHz boards show the average communication overhead can be reduced by 46.38% compared to the original messages. Performance analysis results show our scheme can reduce computational overhead on compression by 31.82% and 19.43% on decompression compared to related schemes. Jin Cao 0001, Zejian Li, Ben Niu 0001, Kwok-Yan Lam, Chihung Chi, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | Easy-Sharing: A Personalized Privacy Diffusion Strategy Generation Method Based on Risk-Return Trade-OffabstractIn the realm of social networks, individuals frequently engage in self-disclosure to gain social influence. However, this behavior simultaneously exposes users to significant privacy risks. Social platforms typically allow users to establish privacy diffusion control strategies, such as selecting the audience for their information. Nevertheless, the lack of privacy awareness and extensive social connections make this task time-consuming and labor-intensive for users. To address this challenge, this paper presents an automated method Easy-Sharing to assist in the effective selection of appropriate seed nodes (initial recipients), aiming to balance social influence and privacy risks according to the user’s privacy preference. This method leverages an advanced VAE-based model to predict information diffusion and proposes a privacy strategy generation method based on a risk-return trade-off. This research contributes to the development of more user-friendly and privacy-conscious social networking tools, ultimately enhancing user experience and safeguarding personal information. Ben Niu 0001, Jin Cao 0001 |
HPCC | 1 |
| 2024 | Interpreting Memorization in Deep Learning from Data DistributionabstractA deep learning model can be vulnerable to a membership inference attack (MIA) which allows an attacker to determine if a specific data record was used for its training. In this paper, we investigate the unfairness of disparate vulnerability to MIA across different subgroups in terms of their data distributions. We propose three practical methods to characterize the distribution of complex training data for deep learning models, which are validated to be effective in identifying the vulnerable data records. We then provide a theoretical definition for MIA vulnerability. Experimental results demonstrate the impact of data distribution on disparate vulnerability, where the out-of-distribution outliers are much more easily attacked than normal data records. Even if the accuracy of MIA looks no better than random guessing over the whole population, there are certain groups of "outliers" can be significantly more vulnerable than others. For example, the attack accuracy on examples with the largest 10% outlierness is 15% higher than that on in-distribution examples. Shoukun Guo, Fenghua Li 0001, Jin Cao 0001, Ben Niu 0001 |
ICASSP | 6 |
| 2024 | ADP-VFL: An Adaptive Differential Privacy Scheme for VPP Based on Federated LearningabstractIn recent years, with the remarkable development of Virtual Power Plants (VPP) and the surge in the number of Electric Vehicles (EVs), the issue of data privacy leakage has become increasingly prominent. The effectiveness of existing federated learning schemes in mitigating data privacy leakage, it still faces potential threats such as inference attacks and user and server collusion. To protect the privacy of federated learning, some schemes have introduced differential privacy(DP). Nevertheless, applying DP will inevitably affect the accuracy to some extent. In this paper, we propose an adaptive differential privacy scheme for VPP based on federated learning, named ADP-VFL. Our ADP-VFL scheme can achieve data privacy preservation by transmitting the noise-added data as a chain, defend against inference attacks by innovating offset noise mechanism and a parallel transmission scheme. The performance evaluation results demonstrate that the proposed scheme can improve the aggregation accuracy and reduces the communication overhead. Mi Wen, Weiwei Li 0007, Ben Niu 0001, Weidong Qiu, Fenghua Li 0001 |
ICC | 4 |
| 2024 | UAVA: Unmanned Aerial Vehicle Assisted Vehicular Authentication Scheme in Edge Computing NetworksabstractIn the pursuit of autonomous driving and intelligent traffic management, the core goal of 5G Vehicle-to-Everything (V2X) communication is to enhance the safety and efficiency of transportation systems. Modern transportation networks have evolved into 3-D structures, including bridges and tunnels from traditional 2-D ones, which poses a challenge to fixed base stations-based networks reliant on supporting continuous and seamless coverage. Against this backdrop, unmanned aerial vehicles (UAVs) play a crucial role in developing multidimensional wireless networks due to their flexibility and functionality. This article proposes a UAV-assisted vehicle authentication (UAVA) scheme. It harnesses the efficiency of edge computing and the security of zero-trust architecture, focusing on enhancing the safety and efficiency of V2X communications. The UAVA scheme employs Chebyshev chaotic mapping and elliptic curve cryptography to strengthen communication security, adapting to the dynamic interactions between vehicles and UAVs. We validate the security using BAN logic and the Scyther tool and assess performance through experiments in a real hardware environment. The results indicate that UAVA offers higher security and lower communication overhead in serverless scenarios compared to existing solutions. These comprehensive evaluations show the potential of UAVA for application in intelligent transportation systems, especially in ensuring secure communications. Zhenyang Guo, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Internet Things J. | 5 |
| 2024 | ADEAS: Authentication Using Doppler Effect of Acoustic Signals Caused by Hands MovingabstractPresently, the prevalent authentication approaches in smartphones are susceptible to interference from light, noise, temperature, and the risk of replay attacks. In the light of these vulnerabilities, and taking into account user behavior alongside smartphone interaction patterns, we have developed an innovative behavioral-based authentication system. This system harnesses the distinctiveness of individual keystroke dynamics for secure user authentication, offering resilience against noise and light fluctuations. In this unique approach, our smartphone’s speakers and microphones emit and capture high-frequency acoustic signals (ASs). To the best of our knowledge, this is the first instance of employing the Doppler effect generated by the high-frequency AS in response to keystroke activity as a distinctive user feature. Our definition of “keystroke behavior” encompasses the motions involved in tapping screen buttons while holding the smartphone, effectively capturing unique user attributes without necessitating any special procedures or passwords. Our initial experiments have convincingly shown that the AS Doppler effect, triggered by keystroke actions, is uniquely identifiable per user during button presses. Subsequently, we utilized a convolutional autoencoder (CAE) to distill keystroke behaviors from the reflected signals, employing an one-class support vector machine (OCSVM) for user authentication and identification processes. We then implemented a prototype of this scheme on smartphones and rigorously tested its performance across four real-world scenarios. The outcomes are promising, demonstrating that our scheme not only withstands disturbances from noise and light but also achieves an impressive average accuracy rate of 95.08%. Regarding security, it effectively thwarts replay and record attacks, further underscoring its robustness and reliability. Zhenyang Guo, Jin Cao 0001, Ben Niu 0001, Ang Li 0005, Hui Li 0006 |
IEEE Internet Things J. | 5 |
| 2024 | CEAMP: A Cross-Domain Entity Authentication and Message Protection Framework for Intra-Vehicle NetworkabstractController Area Network (CAN) is the most wide-used bus system in Intra-Vehicle Networks(IVN). However, the nature of broadcast communication and the lack of security mechanisms make the CAN bus extremely fragile against malicious attacks. Although there are works protecting IVN, most of them are not feasible when applied to real vehicles because they do not consider the IVN node capability. In this paper, we propose a security framework for the CAN bus, covering ECU entity identity management and authentication, symmetric key generation and update, intra-domain, cross-domain secure transmission, and sensitivity-based security classification methods. We formally verify our protocols using the up-to-date tool Tamarin and simulate real attacks in a simulation environment and the results show that the proposed protocol can resist these attacks. By the use of speck encryption and the Chaskey MAC algorithm in our schemes, the analysis results show that the increased time of a frame for a single ECU in our proposed intra-domain scheme is$2.09~ms$to$2.78~ms$on Arduino Mega, and$121.65 \mu s$to$152.15 \mu s$on Arduino DUE, which takes up$6.08\%$to$7.61\%$of a 10ms cyclic time frame. And in the cross-domain scheme is$2.55~ms$to$3.24~ms$on Arduino Mega, and$134.30 \mu s$to$164.80 \mu s$on Arduino DUE, which takes up$6.72\%$to$8.24\%$of a 10ms frame. To the best of our knowledge, this is the first time an IVN cross-domain secure transmission protocol has been proposed without changing the IVN network topology or the CAN protocol. Our work brings practical protection to IVN. Jin Cao 0001, Jiajia Liu 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | An Anonymous and Secure Data Transmission Mechanism With Trajectory Tracking for D2D Relay Communication in 3GPP 5G NetworksabstractDevice-to-device (D2D) communication, as a traffic offloading technology in the fifth-generation (5G) network, can be widely used in several scenarios to provide 5G characteristics of higher speed, lower latency, and larger capacity. D2D data transmission over wireless channels among mobile devices is vulnerable to security threats and privacy violations from third parties and relay nodes. However, academia and industry have yet to propose relevant schemes or standards for D2D relay data transmission scenarios. We first propose a generic construction for D2D relay communication in this paper. Then, a concrete anonymous and secure D2D data transmission scheme with trajectory tracking is presented based on Chebyshev polynomials, hash-based message authentication code, and symmetric encryption. We employ a formal verification tool -Tamarin, modal logic analysis -BAN logic, and informal security analysis to demonstrate the security features of the proposed scheme. The performance evaluation shows that the proposed scheme can achieve desirable efficiency compared with other related schemes. Finally, we developed an APP‘, D2DWatchmen’, to simulate the whole protocol and test its robustness and real execution time, where the result shows good availability and effectiveness. Yunqing Sun, Jin Cao 0001, Xiongpeng Ren, Canhui Tang, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | A UAV-Assisted UE Access Authentication Scheme for 5G/6G NetworkabstractUnmanned Aircraft Vehicles (UAVs) equipped with base stations can assist ground User Equipments (UEs) in accessing the 5G/6G network. Due to the UAV’s high autonomy, easy configuration, and strong dynamic deployment capabilities, UAV-assisted ground UEs to access the 5G/6G network can effectively expand the communication network coverage. However, some vulnerabilities exist, such as eavesdropping attack, impersonation attack, etc. In addition, the 3rd Generation Partnership Project (3GPP) committee has proposed that the UAV can employ the primary authentication mechanism (i.e., 5G-AKA) to connect to the network. Nevertheless, the primary authentication mechanism 5G-AKA has some security problems. In this paper, we first improve the existing 5G-AKA, which resists quantum attack and traceability attack and consumes moderate signaling overhead and short running time. Then, based on the improved 5G-AKA protocol, we propose a UAV-assisted UE access authentication scheme for the 5G/6G network. In the proposed scheme, the UAV can perform the service access authentication process to access the 5G/6G core network and then execute the UAV-assisted UE access authentication process to assist UE in obtaining network services. Additionally, the ground UE can perform a fast and secure handover process with the target UAV to ensure continuous network services. The automation verification tool Tamarin is employed to verify the security of the proposed scheme. Additionally, we implement the improved 5G-AKA protocol and the existing 5G-AKA protocol on Field Programmable Gate Array (FPGA) to test their running time. The security and performance evaluation results show that the proposed scheme provides robust security with moderate efficiency. Ruhui Ma, Jin Cao 0001, Shiyang He, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2023 | A Sensitivity-aware and Block-wise Pruning Method for Privacy-preserving Federated LearningabstractFederated learning (FL) is a distributed learning framework that can reduce privacy risks by not directly sharing private data. However, recent works have shown that the adversary can launch data reconstruction attacks utilizing the gradients or model updates shared by clients. Existing defenses either fail to provide sufficient privacy guarantee or incur significant drop in model accuracy. To achieve a good privacy-utility tradeoff, we propose a novel block-wise pruning method. It mitigates the privacy leakage by locating and quantifying the privacy risk of a model at a finer-grained level. Specifically, we define the sensitivity metric to calculate the gradient sensitivity w.r.t the input to quantify privacy leakage risk of each block. Then we divide the entire model into same-sized blocks and sort them based on the sensitivity metrics. We select part of the blocks with least sensitivity values as the pruned model to be communicated during the client-server interaction. To evaluate the effectiveness and efficiency of our defense, we conduct experiments on MNIST and CIFAR10 for defending against the DLG attack and GS attack. Results demonstrate that our proposed method can significantly mitigate gradient leakage against both DLG attack and GS attack with as much as 20× mean squared errors between the reconstructed data and the raw data with only modest accuracy drop, compared with baseline defenses. Meanwhile, the communication cost between the server and clients is also reduced. Ben Niu 0001, Shoukun Guo, Jin Cao 0001, Fenghua Li 0001 |
GLOBECOM | 1 |
| 2023 | Interpreting Disparate Privacy-Utility Tradeoff in Adversarial Learning via Attribute CorrelationabstractAdversarial learning is commonly used to extract latent data representations which are expressive to predict the target attribute but indistinguishable in the privacy attribute. However, whether they can achieve an expected privacy-utility tradeoff is of great uncertainty. In this paper, we posit it is the complex interaction between different attributes in the training set that causes disparate tradeoff results. We first formulate the measurement of utility, privacy and their tradeoff in adversarial learning. Then we propose the metrics of Statistical Reliability (SR) and Feature Reliability (FR) to quantify the relationship between attributes. Specifically, SR reflects the co-occurrence sampling bias of the joint distribution between two attributes. Beyond the explicit dependence, FR exploits the intrinsic interaction one attribute exerts on the other via exploring the representation disentanglement. We validate the metrics on CelebA and LFW dataset with a suite of target-privacy attribute pairs. Experimental results demonstrate the strong correlations between the metrics and utility, privacy and their tradeoff. We further conclude how to use SR and FR as a guide to the setting of the privacy-utility tradeoff parameter. Yahong Chen, Ang Li 0005, Binghui Wang, Yiran Chen 0001, Fenghua Li 0001, Jin Cao 0001, Ben Niu 0001 |
WACV | 8 |
| 2023 | LK-AKA: A lightweight location key-based authentication and key agreement protocol for S2S communication
Jin Cao 0001, Xiongpeng Ren, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
Comput. Commun. | 4 |
| 2023 | FHAP: Fast Handover Authentication Protocol for High-Speed Mobile Terminals in 5G Satellite-Terrestrial-Integrated NetworksabstractThe integration of satellite and terrestrial networks presents new opportunities and challenges for high speed rail (HSR) communications. Since the HSR runs vary fast, user terminals on the HSR have to perform handover authentication when the HSR passes through different terrestrial base stations or satellite coverage areas. To improve the security and robustness of HSR communication services, a fast handover authentication protocol (FHAP) for high-speed mobile terminals in the 5G satellite–terrestrial-integrated networks (STNs) is proposed. In the FHAP, user terminals in the same carriage form a temporary group managed by a relay node. The prehandover authentication mechanism is employed, in which the terrestrial 5G core network configures the preauthentication information to multiple access nodes based on the Chinese Remainder Theorem according to the location information of the HSR. Thus, group members and one of the access nodes can achieve fast handover authentication with the preconfigured information. Considering that HSR has a high running speed, when handover authentication fails, user terminals can perform handover authentication with other access nodes, and the probability of handover authentication failure caused by a single access node can be effectively reduced. We use the protocol verification tool Scyther and the Burrows–Abadi–Needham (BAN) logic to prove the security of the FHAP and compare it with other similar protocols in terms of signaling, bandwidth, and computational overhead. The analysis results show that the FHAP satisfies better security properties and has excellent performance. Jin Cao 0001, Ruhui Ma, Lifu Cheng, Lilan Chen, Ben Niu 0001, Hui Li 0006 |
IEEE Internet Things J. | 6 |
| 2023 | Go-Sharing: A Blockchain-Based Privacy-Preserving Framework for Cross-Social Network Photo SharingabstractThe evolution of social media has led to a trend of posting daily photos on online Social Network Platforms (SNPs). The privacy of online photos is often protected carefully by security mechanisms. However, these mechanisms will lose effectiveness when someone spreads the photos to other platforms. In this article, we propose Go-sharing, a blockchain-based privacy-preserving framework that provides powerful dissemination control for cross-SNP photo sharing. In contrast to security mechanisms running separately in centralized servers that do not trust each other, our framework achieves consistent consensus on photo dissemination control through carefully designed smart contract-based protocols. We use these protocols to create platform-free dissemination trees for every image, providing users with complete sharing control and privacy protection. Considering the possible privacy conflicts between owners and subsequent re-posters in cross-SNP sharing, we design a dynamic privacy policy generation algorithm that maximizes the flexibility of re-posters without violating formers’ privacy. Moreover, Go-sharing also provides robust photo ownership identification mechanisms to avoid illegal reprinting. It introduces a random noise black box in a two-stage separable deep learning process to improve robustness against unpredictable manipulations. Through extensive real-world simulations, the results demonstrate the capability and effectiveness of the framework across a number of performance metrics. Zhe Sun 0005, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001, Zixu Zhang, Chunhao Zheng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Crafting Text Adversarial Examples to Attack the Deep-Learning-based Malicious URL DetectionabstractDetecting malicious URLs is of great significance to reduce cyber crimes and maintain Internet security. Currently, Deep Learning (DL) techniques have been widely used to improve the classical malicious URL detection models, as DL-based detection models can perform an in-depth analysis of the text information of the URL, and detect the fishing URLs of unknown cyber attack types with high accuracy. Any missed blocking of malicious URLs can potentially result in a huge loss of information and property. In this paper, we focus on the vulnerability of the existing DL-based malicious URL detection models and show that they are sensitive to adversarial samples. First, we construct URL adversarial samples based on the component-level and character-level perturbations and use them to attack mainstream DL-based detection models, resulting in obvious decreases in the detection accuracies. Meanwhile, the perturbations are under the constraints that each adversarial sample URL is hardly distinguished from the original URL with naked eyes. Furthermore, under most circumstances, the adversarial samples constructed by replacing 14 types of characters and perturbing other all components except the scheme component lead to the largest increased number of missed blocking of malicious URLs, i.e., a bigger drop in the accuracy than other constructed methods. Finally, extensive experiments demonstrate the effectiveness of our adversarial examples. Even if the adversarial training is used against our adversarial samples, the adversarial samples still work and bring oblivious decreases in their accuracy. Zuquan Peng, Yuanyuan He 0002, Zhe Sun 0005, Jianbing Ni, Ben Niu 0001, Xianjun Deng |
ICC | 5 |
| 2022 | DP-Opt: Identify High Differential Privacy Violation by Optimization
Ben Niu 0001, Zejun Zhou, Yahong Chen, Jin Cao 0001, Fenghua Li 0001 |
WASA (2) | 1 |
| 2022 | EAP-DDBA: Efficient Anonymity Proximity Device Discovery and Batch Authentication Mechanism for Massive D2D Communication Devices in 3GPP 5G HetNetabstractDevice-to-device (D2D) communication as direct communication technology has many application scenarios and plays a very important role in the fifth-generation (5G) era. Using D2D communication in third generation partnership project (3GPP) 5G Heterogeneous Network (HetNet) can effectively relieve the network traffic pressure and reduce the energy consumption of the base station. However, there are numerous security threats in D2D applications since the D2D communication remains in the early stage. The existing standards and solutions rarely consider device discovery, efficient authentication, mutual authentication, and key negotiation with privacy protection for D2D user equipment (UE) in heterogeneous access scenarios. In this article, we present a unified efficient anonymity proximity device discovery and batch authentication mechanism for heterogeneous D2D UEs based on a new proposed efficient pairing-free certificateless batch signature (CLBS), the identity-based prefix encryption and Chinese remainder theorem (CRT). Our proposed scheme can be applied to all the 5G heterogeneous access scenarios of D2D communication. The security analysis and performance results show that our scheme can achieve mutual authentication, key agreement, identity privacy protection, batch verification, and resist several protocol attacks with ideal efficiency. Yunqing Sun, Jin Cao 0001, Maode Ma, Yinghui Zhang 0002, Hui Li 0006, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | PrivacyEye: A Privacy-Preserving and Computationally Efficient Deep Learning-Based Mobile Video Analytics SystemabstractLarge volumes of video data recorded by the increasing mobile devices and embedded sensors can be leveraged to answer queries of our lives, physical world and our evolving society. Especially, the rapid development of convolutional neural networks (CNNs) in the past few years offers the great advantage for multiple tasks in video analysis. However, adopting running CNNs directly on mobile devices and embedded sensors for video analytics brings heavy burden due to their limited capacity, especially for learning a large volume of data. A promising approach is to outsource the computation-intensive part of CNN to cloud. However, the reveal of data to cloud may cause privacy leakage. In addition, the cloud-assisted approach may also bring some communication efficiency challenges for large volume of data. To address both privacy and efficiency issues, we design a privacy-preserving and computationally efficient framework for mobile video analytics. To protect the private information, we split the CNN model into two subnetworks, and first part is used as a feature extractor deployed in the mobile side and the second part is utilized as a classifier deployed in the cloud side. A specific-designed adversarial training process is adopted in order to extract features for normal task classification while hiding the features for sensitive task. In addition, to improve video process efficiency, we design a two-stage framework. The first stage is to extract key frames and necessary intermediate frames, while skipping redundant ones. The second stage is to extract the features of key frames by CNN-based feature extractor but apply optical-flow-based feature propagation algorithm to obtain the features of intermediate frames. Extensive experiments demonstrate our proposed system PrivacyEye can effectively protect private information while keep the accuracy of the normal tasks with less than 2 percent drop, and it saves up to 82.9 percent execution time and 78.8 percent energy consumption. Wei Du 0009, Ang Li 0005, Pan Zhou 0001, Ben Niu 0001, Dapeng Oliver Wu |
IEEE Trans. Mob. Comput. | 4 |
| 2022 | Eclipse: Preserving Differential Location Privacy Against Long-Term Observation AttacksabstractMechanisms built upon geo-indistinguishability render location privacy, where a user can submit obfuscated locations to Location-Based Service providers but still be able to correctly utilize services. However, these mechanisms are vulnerable under inference attacks. Particularly, with background knowledge of a user’s obfuscated locations, an attacker can infer actual locations by carrying out long-term observation attacks. Unfortunately, how to defend long-term observation attacks in the field of differential location privacy remains open. In this paper, we first demonstrate the vulnerabilities of existing mechanisms under long-term observation attacks. In light of these vulnerabilities, we devise a novel mechanism, referred to as Eclipse, which bridges the gap between location protection and usability of services. Specifically, we harness geo-indistinguishability and$k$-anonymity to obfuscate locations and hide each location based on an anonymity set. As a result, our mechanism effectively perturbs the distribution of locations and suppresses leakage under long-term observation attacks. Moreover, the set of possible outputs is utilized to minimize the impacts to usability and correctness. We formally define and rigorously prove the security of the proposed mechanism by leveraging differential privacy. Moreover, we implement the proposed mechanism and conduct a series of experiments on real-world datasets to demonstrate its efficacy and efficiency. Ben Niu 0001, Yahong Chen, Zhibo Wang 0001, Fenghua Li 0001, Boyang Wang 0001, Hui Li 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2022 | A Framework for Personalized Location PrivacyabstractLocation privacy has been one of the most important research areas over recent years, and many location Privacy Preserving Mechanisms (PPMs) have been proposed. Each PPM typically achieves certain tradeoffs between privacy protection and resource consumption, and no PPM performs perfectly in all cases. Instead of designing one PPM that works for all cases, this paper studies how to make the best use of multiple single PPMs for location privacy protection in different scenarios. In particular, we propose a general framework called SmartGuard, which dynamically selects the best privacy preservation strategy for a user based on her preferences and the current status of her mobile device. SmartGuard quantifies user privacy under various scenarios, models the effects of different PPMs on several key factors such as the remaining battery level and network bandwidth, and then recommends the best privacy strategy for the user. To illustrate how our SmartGuard works, we apply it to a specific scenario of LBSs and implement it on Android based phones. Evaluation results show that our solution outperforms existing PPMs under various scenarios. Ben Niu 0001, Guohong Cao, Fenghua Li 0001, Hui Li 0006 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | AdaPDP: Adaptive Personalized Differential PrivacyabstractUsers usually have different privacy demands when they contribute individual data to a dataset that is maintained and queried by others. To tackle this problem, several personalized differential privacy (PDP) mechanisms have been proposed to render statistical information of the entire dataset without revealing individual privacy. However, existing mechanisms produce query results with low accuracy, which leads to poor data utility. This is primarily because (1) some users are over protected; (2) utility is not explicitly included in the design objective. Poor data utility impedes the adoption of PDP in the real-world applications. In this paper, we present an adaptive personalized differential privacy framework, called AdaPDP. Specifically, to maximize data utility in different cases, AdaPDP adaptively selects underlying noise generation algorithms and calculates the corresponding parameters based on the type of query functions, data distributions and privacy settings. In addition, AdaPDP performs multiple rounds of utility-aware sampling to satisfy different privacy requirements for users. Our privacy analysis shows that the proposed framework renders rigorous privacy guarantee. We conduct extensive experiments on synthetic and real-world datasets to demonstrate the much less utility losses of the proposed framework over various query functions. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Zhibo Wang 0001, Fenghua Li 0001, Jin Cao 0001 |
INFOCOM | 1 |
| 2021 | Weighted distributed differential privacy ERM: Convex and non-convex
Yilin Kang 0002, Yong Liu 0018, Ben Niu 0001, Weiping Wang 0005 |
Comput. Secur. | 3 |
| 2020 | A Framework to Preserve User Privacy for Machine Learning as a ServiceabstractSuffered from the contradiction between the limited capacity of local devices and large size of DNN models, a practical solution is transferring the heavy computational tasks from the local to the server side such as cloud. However, the untrusted server naturally requires all the user data to train neural networks and infer results, which causes the asset loss of the local and raises serious privacy concerns on user's sensitive information. To solve this problem in scenarios of machine learning as a service, we propose a general framework to balance the user privacy, model accuracy and training efficiency, simultaneously. Specifically, our representative subset selection algorithm takes the training value of data into account, selecting the most representative subset from the training data, in order to mitigate the loss of data assets, lower down the transmission overhead from the local to the server and lessen the training burden on the server at the same time. We also design a noisy representation transformation algorithm applying on the features extracted by neural networks to further perturb the data within the selected representative subset. Extensive experiments demonstrate that our framework can run locally with little sacrifice on the computation resource. It can not only protect private data before uploading, but also promote the training efficiency of servers. Ben Niu 0001, Yahong Chen, Ang Li 0005, Wei Du 0009, Jin Cao 0001, Fenghua Li 0001 |
GLOBECOM | 1 |
| 2020 | Towards compression-resistant privacy-preserving photo sharing on social networksabstractThe massive photos shared through the social networks nowadays, e.g., Facebook and Instagram, have aided malicious entities to snoop private information, especially by utilizing deep neural networks (DNNs) to learn from those personal photos. To protect photo privacy against DNNs, recent advances adopting adversarial examples could successfully fool DNNs. However, they are sensitive to those image compression methods that are commonly used on social networks to reduce transmission bandwidth or storage space. A recent work proposed to resist JPEG compression, while the compression methods adopted in social networks are black boxes, and variation of compression methods would significantly degrade the resistance. Zhibo Wang 0001, Hengchang Guo, Mengkai Song, Siyan Zheng, Qian Wang 0002, Ben Niu 0001 |
MobiHoc | 7 |
| 2020 | SmartSwitch: Efficient Traffic Obfuscation Against Stream Fingerprinting
Ben Niu 0001, Boyang Wang 0001 |
SecureComm (1) | 2 |
| 2020 | A Secure Authentication Scheme for Remote Diagnosis and Maintenance in Internet of VehiclesabstractDue to the low latency and high speed of 5G networks, the Internet of Vehicles (IoV) under the 5G network has been rapidly developed and has broad application prospects. The Third Generation Partnership Project (3GPP) committee has taken remote diagnosis as one of the development cores of IoV. However, how to ensure the security of remote diagnosis and maintenance services is also a key point to ensure vehicle safety, which is directly related to the safety of vehicle passengers. In this paper, we propose a secure and efficient authentication scheme based on extended chebyshev chaotic maps for remote diagnosis and maintenance in IoVs. In the proposed scheme, to provide strong security, anyone, such as the vehicle owner or the employee of the Vehicle Service Centre (VSC), must enter the valid biometrics and password in order to enjoy or provide remote diagnosis and maintenance services, and the vehicle and the VSC should authenticate each other to ensure that they are legitimate. The security analysis and performance evaluation results show that the proposed scheme can provide robust security with ideal efficiency. Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001, Lihua Yin |
WCNC | 5 |
| 2020 | Utility-aware Exponential Mechanism for Personalized Differential PrivacyabstractPersonalized Differential Privacy (PDP) was proposed to satisfy users' different privacy requirements. However, most of the existing PDP mechanisms may significantly destroy the utility of released statistical results. Differentially private statistical results with poor utility may mislead the data analysts, thus it may even decrease the acceptability of the technique used to protect data privacy. Therefore, in this paper, our goal is to pursue higher data utility while satisfying personalized differential privacy. To achieve this goal, we propose the Utility-aware Personalized Exponential Mechanism (UPEM) to effectively achieve PDP while pursuing better utility. UPEM distinguishes the different possible results with the same personalized score, which is used in Personalized Exponential Mechanism (PEM) [1]. PEM considers the personalized privacy budgets of changing elements to achieve PDP. Based on PEM, our UPEM further considers the quantitative changes of these changing tuples to enhance the utility. We confirm the effectiveness and efficiency of UPEM through extensive experiments. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Jin Cao 0001, Fenghua Li 0001 |
WCNC | 1 |
| 2020 | A personalized range-sensitive privacy-preserving scheme in LBSsabstractSummary Mobile social network has become a necessary part in our daily life, and location‐based services (LBSs) provide unprecedented convenience to mobile users. However, these attracting services are accompanied with privacy disclosures, including location privacy and query privacy. Mobile users have to expose their personal information to untrusted location‐based service provider (LSP) in order to obtain relevant service data. To address these privacy issues, we proposed a personalized range‐sensitive privacy‐preserving scheme, called PRPS, which considers the relationship between locations, query ranges, and query contents. Moreover, PRPS employs map storing algorithm (MSA) to facilitate the storage of two‐dimensional local map, reducing the cost of storage. Furthermore, range estimating algorithm (REA) adopts binary quad‐tree to decide the query radius of each submitted location, avoiding inference attacks by adversary. The requirements generating algorithm (RGA) selects relevant query content for each dummy location, guaranteeing mobile user's location privacy and query privacy. Finally, we illustrate the privacy analysis to proof PRPS's privacy degree; then, the performance and privacy evaluation results indicate that the proposed PRPS is effective and efficient. Weihao Li 0004, Ben Niu 0001, Jin Cao 0001, Yurong Luo, Hui Li 0006 |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | Exploiting location-related behaviors without the GPS data on smartphones
Fenghua Li 0001, Xinyu Wang 0004, Ben Niu 0001, Hui Li 0006, Chao Li 0027 |
Inf. Sci. | 3 |
| 2020 | Privbus: A privacy-enhanced crowdsourced bus service via fog computing
Yuanyuan He 0002, Jianbing Ni, Ben Niu 0001, Fenghua Li 0001, Xuemin Shen |
J. Parallel Distributed Comput. | 3 |
| 2020 | Achieving Privacy-Preserving Group Recommendation with Local Differential Privacy and Random TransmissionabstractGroup activities on social networks are increasing rapidly with the development of mobile devices and IoT terminals, creating a huge demand for group recommendation. However, group recommender systems are facing an important problem of privacy leakage on user’s historical data and preference. Existing solutions always pay attention to protect the historical data but ignore the privacy of preference. In this paper, we design a privacy-preserving group recommendation scheme, consisting of a personalized recommendation algorithm and a preference aggregation algorithm. With the carefully introduced local differential privacy (LDP), our personalized recommendation algorithm can protect user’s historical data in each specific group. We also propose an Intra-group transfer Privacy-preserving Preference Aggregation algorithm (IntPPA). IntPPA protects each group member’s personal preference against either the untrusted servers or other users. It could also defend long-term observation attack. We also conduct several experiments to measure the privacy-preserving effect and usability of our scheme with some closely related schemes. Experimental results on two datasets show the utility and privacy of our scheme and further illustrate its advantages. Ben Niu 0001, Lihua Yin, Fenghua Li 0001 |
Wirel. Commun. Mob. Comput. | 3 |
| 2019 | HideMe: Privacy-Preserving Photo Sharing on Social NetworksabstractPhoto sharing on Online Social Networks (OSNs) has become one of the most popular social activities in our daily life. However, some associated friends or bystanders in the photos may not want to be viewed due to privacy concerns. In this paper, we propose the design, implementation and evaluation of HideMe, a framework to preserve the associated users’ privacy for online photo sharing. HideMe acts as a plugin to existing photo sharing OSNs, and it enables the following: a) extraction of factors when users upload their photos, b) associated friends in the uploaded photos are able to set their own privacy policies based on scenarios, instead of a photo-by-photo setting, c) any user in other friend’s uploaded photos could be hidden away from unwanted viewers based on one time policy generation. We also design a distance-based algorithm to identify and protect the privacy of bystanders. Moreover, HideMe not only protects users’ privacy but also reduces the system overhead by a carefully designed face matching algorithm. We have implemented a prototype of HideMe, and evaluation results have demonstrated its effectiveness and efficiency. Fenghua Li 0001, Zhe Sun 0005, Ang Li 0005, Ben Niu 0001, Hui Li 0006, Guohong Cao |
INFOCOM | 4 |
| 2019 | Quantum-Resistance Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G NetworksabstractThe Narrow Band Internet of Things (NB-IoT) system has become an important branch of the Internet of Everything and is an indispensable part in future fifth Generation (5G) network. However, there is currently no effective access authentication scheme for the NB-IoT system in the future 5G network. According to the current 3GPP standard, NB-IoT devices still use the traditional access authentication method to perform the mutual authentication with the network, which may bring a lot of signaling and communication overheads. This problem will be more prominent when sea of NB-IoT devices simultaneously are activated in the 5G network. In this paper, we propose a quantum-resistance access authentication and data distribution scheme for massive NB-IoT devices. This scheme can implement access authentication and data transmission for a group of NB-IoT devices at the same time based on the lattice-based homomorphic encryption technology. Our scheme can not only greatly reduce the network burden, but also can achieve the strong security including privacy protection and resisting quantum attacks. Performance analysis results show that our solution has the desired efficiency. Pu Yu, Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
WCNC | 5 |
| 2019 | Enhancing Privacy and Availability for Data Clustering in Intelligent Electrical Service of IoTabstractThe ever-growing demand for electrical energy of sensing devices in the Internet of Things (IoT) has led to generating large amounts of electricity consumption data. Electricity service providers often use wireless sensor networks to collect sensing devices' electricity consumption data for statistical analysis, so as to provide sensing devices with improved electrical services. As an important data mining technique, while data clustering excels in dealing with such massive data, it imposes the risk of privacy disclosure in the process of data clustering. In an effort of solving this problem, Blum et al. proposed a differential privacy k-means algorithm, effectively preventing privacy disclosure. However, the availability of data clustering results is reduced due to the data distortion in Blum's algorithm. In this paper, we propose a privacy and availability data clustering (PADC) scheme based on k -means algorithm and differential privacy, which enhances the selection of the initial center points and the distance calculation method from other points to center point. Moreover, PADC attempts to reduce the outlier effect through detecting outliers during the clustering process. Security analysis indicates that our scheme satisfies the goal of differential privacy and prevents privacy information disclosure. Meanwhile, performance evaluation shows that our scheme, at the same privacy level, improves the availability of clustering results compared to the existing differential privacy k-means algorithms, suggesting that our proposed PADC scheme outperforms others for intelligent electrical service in IoT. Jinbo Xiong, Lei Chen 0029, Mingwei Lin, Dapeng Wu 0002, Ben Niu 0001 |
IEEE Internet Things J. | 7 |
| 2018 | Achieving Personalized k-Anonymity against Long-Term Observation in Location-Based ServicesabstractLocation privacy continues to attract significant attentions from both industry and academia in recent years. However, Location Based Service (LBS) servers or some other adversaries who can monitor a particular user's historical and current status in a long-term way may likely infer user's location privacy. To solve this problem, we propose a Longterm Observation-aware Dummy Selection (LODS) algorithm to achieve k-anonymity for users in LBSs. Different from existing approaches, the LODS takes the historical anonymity sets into account, since mobile users may query LBSs at certain places such as home or office. LODS selects candidate sets containing dummy locations with less number of occurrences firstly, in order to achieve the preferred distribution. Then, LODS further filters out candidate sets with smaller entropy. Finally, we choose the anonymity set with highest Quality of Service (QoS) as the result. Extensive experiment indicates our algorithm can protect user's location privacy effectively against long-term observation, and satisfy user's QoS requirement at the same time. Fenghua Li 0001, Yahong Chen, Ben Niu 0001, Yuanyuan He 0002, Kui Geng, Jin Cao 0001 |
GLOBECOM | 3 |
| 2018 | Privacy-preserving ride clustering for customized-bus sharing: A fog-assisted approachabstractCustomized-bus Sharing Service (CSS) enables a centralized server to schedule comfortable bus trips for users by ride clustering based on the individual requirements. It has been increasingly popular in crowded metropolises, bringing a lot of convenience and reducing trip costs to users. Ride clustering is essential for the server to determine the stops of a customized bus, but it also leads to the exposure of users' current locations and spatio-temporal patterns. Although privacy-preserving ride clustering can generate optimal bus routes, it depends on frequent interactions between users and the server, so all the users should be always online. In this paper, we propose a privacy-preserving ride clustering scheme for CSS to support off-line users, in which fog computing is introduced to assist the server in generating bus route without the exposure of users' travel plans. Fog servers are able to perform ride clustering interacting with the server, after receiving the preferred pick-up and drop-off positions from users. Thus, the users are unnecessary to be always online. In addition, the Paillier cryptosystem and randomization technique are leveraged to protect the user's privacy without sacrificing the clustering quality. Finally, the proposed privacy-preserving ride clustering scheme is demonstrated to have the advantage of low computational and communication overhead with high security guarantees. Yuanyuan He 0002, Jianbing Ni, Ben Niu 0001, Fenghua Li 0001, Xuemin Shen |
WiOpt | 3 |
| 2018 | HAC: Hybrid Access Control for Online Social NetworksabstractThe rapid development of communication and network technologies including mobile networks and GPS presents new characteristics of OSNs. These new characteristics pose extra requirements on the access control schemes of OSNs, which cannot be satisfied by relationship-based access control currently. In this paper, we propose a hybrid access control model (HAC) which leverages attributes and relationships to control access to resources. A new policy specification language is developed to define policies considering the relationships and attributes of users. A path checking algorithm is proposed to figure out whether paths between two users can fit in with the hybrid policy. We develop a prototype system and demonstrate the feasibility of the proposed model. Fangfang Shan, Hui Li 0006, Fenghua Li 0001, Yunchuan Guo, Ben Niu 0001 |
Secur. Commun. Networks | 5 |
| 2017 | TrackU: Exploiting User's Mobility Behavior via WiFi ListabstractWith the prevalence of Location-Based Service (LBS), the concern of location privacy has raised the attention of users in recent years. Although most smartphone users carefully set the location-related permissions of Apps, they ignore the fact that Apps can obtain the location of devices through accessing WiFi list. Therefore, it is necessary to investigate the severe consequence of WiFi list leakage. Taking TrackU, an efficient scheme on Android for example, this paper proves that it is possible to obtain users location data by monitoring the WiFi list, without directly relying on the location-related permissions. At first, the WiFi APs (Access Points) is scanned periodically. Meanwhile, the location provided by LBS providers (e.g, Google or Baidu LBS SDK) is queried. Then a drift adjusting algorithm is proposed to obtain exact locations considering a set of factors, such as the historical location information, the average signal strengths and the changing of WiFi list. Based on the obtained data, we design an activity detection algorithm to infer users daily activities exactly. Finally, we implement the TrackU and carry out a series of experiments with 40 volunteers from 8 cities in China. The experiment results show that our design can detect 91.6% of users activities by monitoring the WiFi list. Fenghua Li 0001, Xinyu Wang 0004, Ben Niu 0001, Hui Li 0006, Chao Li 0027 |
GLOBECOM | 3 |
| 2017 | Trajectory prediction-based handover authentication mechanism for mobile relays in LTE-A high-speed rail networksabstractThe handover mechanism with the assist of mobile relay mounted in high-speed trains has been researched to support continuous communication services for Long-Term Evolution Advanced (LTE-A) high-speed rail networks. According to the third Generation Partnership Project (3GPP) standard, the handover process for Mobile Relay Nodes (MRNs) from a donor eNB (DeNB) to another is the same as that for the common User Equipment (UE), which requires several rounds of message exchange with a complex key management mechanism. In addition, it cannot achieve the mutual authentication in handover procedures. In this paper, we propose a handover authentication mechanism based on trajectory prediction for mobile relays. In our scheme, the mutual authentication and key agreement between a MRN and the target DeNB is accomplished with ideal efficiency. Compared with the current 3GPP standards and other related schemes, our scheme effectively reduces the handover delays and at the same time provides strong security protection. Security analysis by using the formal verification tool AVISPA and SPAN and performance evaluation results show the security and efficiency of our scheme. Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
ICC | 5 |
| 2017 | Impact factor-based group recommendation scheme with privacy preservation in MSNsabstractMobile Social Networks (MSNs) provide a variety of social networking applications in mobile environment, where social group finds and recruits potential members easily. Unfortunately, users enjoy these conveniences at the cost of revealing their personal data. Additionally, people usually ignore a critical factor, Impact Factor (IF), which is used to quantify group members' influence on their groups, since a group member with larger IF generally has a greater influence on potential new member recommendation. In this paper, we propose IF-RG, an IF-based group recommendation scheme with privacy preservation in MSNs. First, we construct a transmission matrix and exploit PageRank algorithm to compute and update group members' IFs. The average variation of IF is formed to measure convergence speed of the iteration method of computing IF. To make sure that the larger IFs, the more influence, IF, Ochiai similarity function and weighted majority rule are integrated in the novel matching degree between stranger and group. The fuzzy matrix algorithm not only protects users' privacy, but also helps our scheme to support group recommendation when not every one in the groups is online. Finally, security and performance are analyzed and evaluated via detailed simulations. Yuanyuan He 0002, Kuan Zhang 0001, Fenghua Li 0001, Ben Niu 0001, Hui Li 0006 |
ICC | 5 |
| 2017 | Pricing Privacy Leakage in Location-Based Services
Fenghua Li 0001, Liang Fang 0009, Ben Niu 0001, Kui Geng, Hui Li 0006 |
WASA | 4 |
| 2017 | Small-world: Secure friend matching over physical world and social networks
Fenghua Li 0001, Yuanyuan He 0002, Ben Niu 0001, Hui Li 0006 |
Inf. Sci. | 3 |
| 2017 | Server-aided private set intersection based on reputation
En Zhang, Fenghua Li 0001, Ben Niu 0001 |
Inf. Sci. | 3 |
| 2016 | Achieving secure and accurate friend discovery based on friend-of-friend's recommendationsabstractFriend discovery has been one of the hot topics in our social activities over the past decade. Mobile users have more opportunities to discover and make new social interactions with others in vicinity to build and extend their social communities. However, the inevitable information releasing conflicts with the increasing privacy concerns. In this paper, we employ the concept of friend-of-friend and design a secure and accurate friend discovery for privacy-aware mobile users in Proximity-based Mobile Social Networks (PMSNs). We first construct a novel similarity function with fully considering the number of common attributes, the corresponding priorities and the ratio of matched attributes over all the inputs. Then we develop a secure friend recommendation phase based on a carefully combination of the commutative encryption function and the bilinear pairings. The security and performance are thoroughly analyzed and evaluated via detailed simulations. Yuanyuan He 0002, Fenghua Li 0001, Ben Niu 0001, Jiafeng Hua |
ICC | 3 |
| 2016 | A practical group matching scheme for privacy-aware users in mobile social networksabstractPrivacy issues in group matching problem have become one of the most important things in Mobile Social Networks (MSNs) currently. Mobile users may feel uncomfortable when releasing personal information to some irrelevant people or groups. In this paper, we propose a practical group matching scheme without employing any Trusted Third Party (TTP) for privacy-aware users in MSNs. We first propose a fuzzy matrix algorithm to generate user's authority instead of complex cryptographic computations to reduce the communication and computation overhead, and thus build a public set to store all the group members' profiles and authorities. As a result, our group matching does not need all the group members are online anymore. Moreover, we utilize the Ochiai similarity considering both of the number of common attributes and the size of each user's profile. The privacy and performance are analyzed and evaluated via detailed simulations. Fenghua Li 0001, Ben Niu 0001, Yuanyuan He 0002, Jiafeng Hua, Hui Li 0006 |
WCNC | 3 |
| 2016 | Time obfuscation-based privacy-preserving scheme for location-based servicesabstractPrivacy issues in Location-Based Services (LBSs) have gained tremendous attentions in literature over recent years. Existing approaches always fail to provide dual privacy protection on both user's location and point of interest (POI), incur endurable system overhead, and produce high quality of services, simultaneously. To address these problems, we propose a time obfuscation-based scheme, termed TOP-privacy, which carefully generates and sends some dummy queries at leisure time to confuse adversaries with some background information. TOP-privacy employs a dummy query generation algorithm, which includes a dummy location selection module and a classified POI pool construction module. It first selects some location candidates with similar location distribution with the real user's, and then determines the optimal POI to construct the dummy query based on the similarity to the user's real POI. Security analysis and evaluation results indicate its effectiveness and efficiency. Fenghua Li 0001, Sheng Wan, Ben Niu 0001, Hui Li 0006, Yuanyuan He 0002 |
WCNC | 3 |
| 2015 | Privacy-preserving strategies in service quality aware Location-Based ServicesabstractThe popularity of Location-Based Services (LBSs) have resulted in serious privacy concerns recently. Mobile users may lose their privacy while enjoying kinds of social activities due to the untrusted LBS servers. Many Privacy Protection Mechanisms (PPMs) are proposed in literature by employing different strategies, which come at the cost of either system overhead, or service quality, or both of them. In this paper, we design privacy-preserving strategies for both of the users and adversaries in service quality aware LBSs. Different from existing approaches, we first define and point out the importance of the Fine-Grained Side Information (FGSI) over existing concept of the side information, and propose a Dual-Privacy Metric (DPM) and Service Quality Metric (SQM). Then, we build analytical frameworks that provide privacy-preserving strategies for mobile users and the adversaries to achieve their goals, respectively. Finally, the evaluation results show the effectiveness of our proposed frameworks and the strategies. Weihao Li 0004, Ben Niu 0001, Hui Li 0006, Fenghua Li 0001 |
ICC | 2 |
| 2015 | Enhancing privacy through caching in location-based servicesabstractPrivacy protection is critical for Location-Based Services (LBSs). In most previous solutions, users query service data from the untrusted LBS server when needed, and discard the data immediately after use. However, the data can be cached and reused to answer future queries. This prevents some queries from being sent to the LBS server and thus improves privacy. Although a few previous works recognize the usefulness of caching for better privacy, they use caching in a pretty straightforward way, and do not show the quantitative relation between caching and privacy. In this paper, we propose a caching-based solution to protect location privacy in LBSs, and rigorously explore how much caching can be used to improve privacy. Specifically, we propose an entropy-based privacy metric which for the first time incorporates the effect of caching on privacy. Then we design two novel caching-aware dummy selection algorithms which enhance location privacy through maximizing both the privacy of the current query and the dummies' contribution to cache. Evaluations show that our algorithms provide much better privacy than previous caching-oblivious and caching-aware solutions. Ben Niu 0001, Xiaoyan Zhu 0005, Guohong Cao, Hui Li 0006 |
INFOCOM | 1 |
| 2015 | A novel attack to spatial cloaking schemes in location-based services
Ben Niu 0001, Xiaoyan Zhu 0005, Jie Chen 0055, Hui Li 0006 |
Future Gener. Comput. Syst. | 1 |
| 2014 | Privacy-area aware dummy generation algorithms for Location-Based ServicesabstractLocation-Based Services (LBSs) have been one of the most popular activities in our daily life. Users can send queries to the LBS server easily to learn their surroundings. However, these location-related queries may result in serious privacy concerns since the un-trusted LBS server has all the information about users and may track them in various ways. In this paper, we propose two dummy-based solutions to achieve k-anonymity for privacy-area aware users in LBSs with considering that side information may be exploited by adversaries. We first choose some candidates based on a virtual circle or grid method, then blur these candidates into the final positions of dummy locations based on the entropy-based privacy metric. Security analysis and evaluation results indicate that the V-circle solution can significantly improve the privacy anonymity level. The V-grid solution can further enlarge the cloaking region while keeping similar privacy level. Ben Niu 0001, Zhengyan Zhang, Xiaoqing Li 0001, Hui Li 0006 |
ICC | 1 |
| 2014 | A fine-grained spatial cloaking scheme for privacy-aware users in Location-Based ServicesabstractIn Location-Based Services (LBSs) mobile users submit location-related queries to the untrusted LBS server to get service. However, such queries increasingly induce privacy concerns from mobile users. To address this problem, we propose FGcloak, a novel fine-grained spatial cloaking scheme for privacy-aware mobile users in LBSs. Based on a novel use of modified Hilbert Curve in a particular area, our scheme effectively guarantees k-anonymity and at the same time provides larger cloaking region. It also uses a parameter σ for users to make fine-grained control on the system overhead based on the resource constraints of mobile devices. Security analysis and empirical evaluation results verify the effectiveness and efficiency of our scheme. Ben Niu 0001, Xiaoyan Zhu 0005, Hui Li 0006 |
ICCCN | 1 |
| 2014 | Achieving k-anonymity in privacy-aware location-based servicesabstractLocation-Based Service (LBS) has become a vital part of our daily life. While enjoying the convenience provided by LBS, users may lose privacy since the untrusted LBS server has all the information about users in LBS and it may track them in various ways or release their personal data to third parties. To address the privacy issue, we propose a Dummy-Location Selection (DLS) algorithm to achieve k-anonymity for users in LBS. Different from existing approaches, the DLS algorithm carefully selects dummy locations considering that side information may be exploited by adversaries. We first choose these dummy locations based on the entropy metric, and then propose an enhanced-DLS algorithm, to make sure that the selected dummy locations are spread as far as possible. Evaluation results show that the proposed DLS algorithm can significantly improve the privacy level in terms of entropy. The enhanced-DLS algorithm can enlarge the cloaking region while keeping similar privacy level as the DLS algorithm. Ben Niu 0001, Xiaoyan Zhu 0005, Guohong Cao, Hui Li 0006 |
INFOCOM | 1 |
| 2014 | EPcloak: An Efficient and Privacy-Preserving Spatial Cloaking Scheme for LBSsabstractLocation-Based Services (LBSs) have become one of the most popular activities and affected our daily life a lot. Mobile users can enjoy kinds of conveniences by submitting their location and interest-related queries to the LBS server. However, since these queries may expose sensitive information to the untrusted LBS server, privacy concerns arise. To address the serious privacy issues, we propose a novel collaborative scheme, EPcloak, which combines a privacy-preserving spatial cloaking algorithm and caching to protect user's privacy. Different from existing schemes, users in EPcloak cache their past service data for future use. When LBSs are needed, a user first uses a Local Searching Algorithm (LSA) to look for service data from the nearby friends of a collaborative group through Ad Hoc networks. If the requirements cannot be satisfied, the user uses a Spatial Cloaking Algorithm (SCA) to forward the query to another user at a certain distance away through a set of forwarders. That user will query the LBS server to get service data for a larger area that can cover the original user's query area, and send the data back to the original user. SCA protects both user's location privacy and query privacy. Evaluation results indicate that our proposed LSA and SCA are effective and efficient. Ben Niu 0001, Xiaoyan Zhu 0005, Weihao Li 0004, Hui Li 0006 |
MASS | 1 |
| 2014 | Are You Really My Friend? Exactly Spatiotemporal Matching Scheme in Privacy-Aware Mobile Social Networks
Ben Niu 0001, Xiuguang Li, Xiaoyan Zhu 0005, Xiaoqing Li 0001, Hui Li 0006 |
SecureComm (2) | 1 |
| 2013 | Weight-aware private matching scheme for Proximity-based Mobile Social NetworksabstractMaking new social interactions with other users in vicinity is a crucial service in Proximity-based Mobile Social Networks (PMSNs), where a user can find a best matching friend directly through the Bluetooth/WiFi interfaces built in her mobile device. In existing work for such services, users have to publish their interests to do the matching. However, it conflicts with users' growing privacy concerns about revealing their interests to strangers. To tackle this problem, we propose Weighted Average Similarity (WAS) algorithm, which considers both the number of common interests and the corresponding weights on them, to protect users' privacy without reliance on any Trusted Third Party (TTP). Users set their interests into several priority levels with different weights, then WAS can provide a high level similarity value among these participants without revealing any information about their common interests. The security and computation/communication overhead of our scheme are thoroughly analyzed and evaluated via detailed simulations. Ben Niu 0001, Xiaoyan Zhu 0005, Zan Li 0001, Hui Li 0006 |
GLOBECOM | 1 |
| 2013 | EPS: Encounter-Based Privacy-Preserving Scheme for Location-Based ServicesabstractLocation-Based Services (LBSs) gain increasing popularity with the development of social networks and mobile devices. The mobile users enjoy convenience by submitting their private information. Nonetheless, the users' sensitive information may be abused by an un-trusted LBS server. Privacy concerned in LBSs can be categorized into two major types: location privacy and query privacy. In this paper, we propose a novel scheme, called Encounter-Based Privacy-Preserving Scheme (EPS), which allows a user to access an LBS server under the protection of k-anonymity on both her location privacy and query privacy. Without reliance on any Trusted Third Party (TTP), EPS uses a buffer on each user's mobile device to collect the queried information of the encountered users. To achieve k-anonymity, a user needs to choose k-1 records from her buffer, with the help of our location obfuscating algorithm and querying algorithm, the user's privacy can be protected. Evaluation results show the effectiveness and efficiency of our proposed EPS. Ben Niu 0001, Xiaoyan Zhu 0005, Xiaosan Lei, Hui Li 0006 |
GLOBECOM | 1 |
| 2013 | MobiCache: When k-anonymity meets cacheabstractLocation-Based Services (LBSs) are becoming increasingly popular in our daily life. In some scenarios, multiple users may seek data of same interest from a LBS server simultaneously or one by one, and they may need to provide their exact locations to the un-trusted LBS server in order to enjoy such a location-based service. Unfortunately, this will breach users' location privacy and security. To address this problem, we propose a novel collaborative system, MobiCache, which combines k-anonymity with caching together to protect user's location privacy while improving the cache hit ratio. Different from the traditional k-anonymity, our Dummy Selection Algorithm (DSA) chooses dummy locations which have not been queried before to increase the cache hit ratio. We also propose an enhanced-DSA to further improve the user's privacy as well as the cache hit ratio by assigning dummy locations which can make more contributions to cache hit ratio. Evaluation results show that the proposed DSA can increase the cache hit ratio and the enhanced-DSA can further improve the cache hit ratio as well as the user's privacy. Xiaoyan Zhu 0005, Haotian Chi, Ben Niu 0001, Zan Li 0001, Hui Li 0006 |
GLOBECOM | 3 |
| 2013 | P-Match: Priority-Aware Friend Discovery for Proximity-Based Mobile Social NetworksabstractWith rapid developments of mobile devices and online social networks, users of Proximity-based Mobile Social Networks (PMSNs) can easily discover and make new social interactions with others at the cost of their growing privacy concerns. To address this problem, we propose a third party free scheme, P-match, to privately match the similarity with potential friends in vicinity. Unlike most existing work, P-match considers both the number of common interests and the corresponding priorities on each of them individually. The security and performance overhead of our scheme are then thoroughly analyzed and evaluated via detailed simulations. Ben Niu 0001, Xiaoyan Zhu 0005, Tanran Zhang, Haotian Chi, Hui Li 0006 |
MASS | 1 |
| 2013 | 3PLUS: Privacy-preserving pseudo-location updating system in location-based servicesabstractLocation-Based Services (LBSs) are becoming increasingly popular with rapid developments of social networks and location aware devices, such as smartphones and tablets. Users query the LBSs server and get service information about their surroundings. Unfortunately, these queries may lead to serious security and privacy concerns. It is very hard for users to access LBSs while keeping their privacy at the same time. To deal with this problem, we propose a novel scheme, called 3PLUS. It can significantly improve users' location privacy without reliance on the Trusted Third Party (TTP). Further more, it is simple to implement, and does not require changing the current structure of LBSs server. Users use a buffer to record the pseudo-locations, which come from both the history locations of herself and the encountered users. When two users encounter, by using their pseudonyms, they randomly choose a pseudo-location from their buffers and exchange with each other. Then she can find and submit k valid locations together to un-trusted LBSs server easily when the service is needed. Our evaluation results indicate us a hidden relationship between k, the buffer size S and exchanging number N. Ben Niu 0001, Xiaoyan Zhu 0005, Haotian Chi, Hui Li 0006 |
WCNC | 1 |
| 2013 | An ultralightweight and privacy-preserving authentication protocol for mobile RFID systemsabstractExisting work on RFID authentication problems always make assumptions that 1) hash function can be fully used in designing RFID protocols; 2) channels between readers and the server are always secure. However, the first assumption is not suitable for EPC Class-1 Gen-2 tags, which has been challenged in many research work, while the second one cannot be adopted in mobile RFID applications where the wireless channels between readers and the server are always insecure. In this paper, we propose a new ultralightweight authentication protocol for mobile RFID systems. We only use bitwise XOR, and special constructed pseudo-random number generators (RNGs) to achieve our aims in insecure mobile RFID environment. Security analysis shows that our protocol can provide several privacy properties and avoid suffering from kinds of attacks, including tag anonymity, tag location privacy, reader privacy, forward secrecy, and mutual authentication, replay attack, desynchronization attack etc. We implement our protocol and compare authentication delays with several existing work, the results indicate us that our protocol significantly improves the efficiency. Ben Niu 0001, Xiaoyan Zhu 0005, Hui Li 0006 |
WCNC | 1 |
| 2012 | A security enhanced authentication and key distribution protocol for wireless networksabstractABSTRACT Authentication and key distribution (AKD) protocols become more and more important in the design of wireless networks. Especially, the communication efficiency and security are the critical factors. In this paper, we first analyse the vulnerabilities of an AKD protocol for wireless networks under three types of attacks. Then, we propose an enhanced AKD protocol to overcome those vulnerabilities with the security functionality to prevent those malicious attacks. Security analysis and formal verification mainly using Automated Validation of Internet Security Protocols and Applications toolkit show that the proposed protocol is secure against those attacks. Copyright © 2011 John Wiley & Sons, Ltd. Maode Ma, Hui Li 0006, Jianfeng Ma 0001, Ben Niu 0001 |
Secur. Commun. Networks | 5 |
| 2012 | Security enhancement of the communication-efficient AUTHMAC_DH protocolsabstractABSTRACT Authentication and key distribution (AKD) protocols have become more important in the design of communication systems. The design criteria of the AKD protocols include the scalability, the communication efficiency, the computational efficiency, and the robustness of security. In this paper, we first analyze the vulnerability of an AKD protocol under the off‐line guessing attack. Then, we propose an enhanced AKD protocol to overcome the vulnerability. Security analysis and formal verification by using AVISPA toolkit show that the proposed protocol can keep all the previous properties and is secure against the off‐line guessing attack. Copyright © 2011 John Wiley & Sons, Ltd. Maode Ma, Hui Li 0006, Jianfeng Ma 0001, Ben Niu 0001 |
Secur. Commun. Networks | 5 |